BIT-mattermost-2024-1949

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/mattermost/BIT-mattermost-2024-1949.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-mattermost-2024-1949
Aliases
Published
2024-12-16T07:16:19.780Z
Modified
2024-12-16T13:41:53.109047Z
Summary
[none]
Details

A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized access to individual posts' contents via carefully timed post creation while another user deletes posts.

Database specific
{
    "cpes": [
        "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*"
    ],
    "severity": "Low"
}
References

Affected packages

Bitnami / mattermost

Package

Name
mattermost
Purl
pkg:bitnami/mattermost

Severity

  • 2.6 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.1.0
Fixed
8.1.9
Introduced
9.4.0
Fixed
9.4.2